Agent skill

Retention Impact Assess

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Conducts retention impact assessments for new processing activities to determine appropriate data retention periods.

Apache-2.0Auto-check passedLegal & Compliance

Install Retention Impact Assess

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill retention-impact-assess -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills retention-impact-assess --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/retention-impact-assess .claude/skills/retention-impact-assess && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
retention-impact-assess
GitHub stars
301
Token cost
~3.7k tokens
SKILL.md length
873 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Conducts retention impact assessments for new processing activities to determine appropriate data retention periods.

  • Works in 5 steps: Scope and Context → Regulatory Requirements Scan → Purpose-Based Retention Determination → …
  • Tasks that involve Privacy and GDPR
  • SKILL.md covers Overview, Legal Foundation, When to Conduct a Retention… and Retention Impact Assessment…, plus 2 more sections
  • Runs Python scripts from its folder

What it does

Retention Impact Assess is an agent skill from mukul975/Privacy-Data-Protection-Skills. Conducts retention impact assessments for new processing activities to determine appropriate data retention periods. Covers regulatory requirements scanning, proportionality review, purpose-based retention determination, and retention period documentation aligned with GDPR Article 5(1)(e) and Article 25 data protection by design. Activate for retention assessment, new processing retention, retention period determination queries.

Its SKILL.md is about 3.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering Privacy and GDPR and Regulatory compliance. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Privacy and GDPR
  • Tasks that involve Regulatory compliance

Example prompts

  • “Use the retention-impact-assess skill to conduct retention impact assessments for new processing activities to determine appropriate data retention…”
  • “/retention-impact-assess”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Scope and Context
  2. Regulatory Requirements Scan
  3. Purpose-Based Retention Determination
  4. Proportionality Review
  5. Retention Period Recommendation

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Retention Impact Assess loads about 3.7k tokens when it runs, and up to ~5.2k if it reads all its reference files. Until then it costs about 114 tokens; SKILL.md has 873 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~114
When it runs · the whole SKILL.md, loaded when a task matches
~3.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 873 words, ~3,659 tokens.

Download SKILL.mdSave it as .claude/skills/retention-impact-assess/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
retention-impact-assess
description
Conducts retention impact assessments for new processing activities to determine appropriate data retention periods. Covers regulatory requirements scanning, proportionality review, purpose-based retention determination, and retention period documentation aligned with GDPR Article 5(1)(e) and Article 25 data protection by design. Activate for retention assessment, new processing retention, retention period determination queries.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
data-retention-deletion
metadata.tags
retention-impact-assessment, retention-determination, storage-limitation, proportionality-review, retention-planning

Retention Impact Assessment

Overview

A Retention Impact Assessment (RIA) is a structured evaluation conducted before commencing new processing activities (or significantly changing existing ones) to determine the appropriate retention period for personal data. The RIA ensures that retention periods are set proactively — by design — rather than retroactively after data has accumulated without defined limits. Under GDPR Article 25, data protection by design requires that storage limitation is considered at the design stage of any processing activity. This skill provides the assessment methodology, regulatory scanning framework, proportionality analysis, and documentation template for determining and justifying retention periods.

GDPR Article 5(1)(e) — Storage Limitation

Personal data shall be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed.

GDPR Article 25 — Data Protection by Design and by Default

The controller shall implement appropriate technical and organisational measures designed to implement data-protection principles, such as data minimisation, in an effective manner and to integrate the necessary safeguards into the processing. This includes proactive determination of retention periods before processing begins.

GDPR Article 35(7)(d) — DPIA Content

Where a Data Protection Impact Assessment is required, it must include the envisaged processing operations and the purposes, including where applicable the legitimate interest pursued (Art. 35(7)(a)), and an assessment of the necessity and proportionality of the processing operations (Art. 35(7)(b)). Retention period determination is a core element of the necessity and proportionality assessment.

GDPR Article 13(2)(a) and Article 14(2)(a) — Transparency

Data subjects must be informed of the period for which personal data will be stored, or the criteria used to determine that period. The RIA produces this information.

When to Conduct a Retention Impact Assessment

Mandatory Triggers
TriggerDescription
New processing activityAny new processing activity involving personal data that is not covered by an existing retention schedule entry
New system/applicationDeployment of a new system, application, or database that will store personal data
Significant change to existing processingChange in purpose, scope, data categories, or technology that materially affects the retention profile
New legal/regulatory requirementNew legislation or regulatory guidance that introduces or modifies retention requirements
Post-breach recommendationFollowing a data breach where excessive retention was identified as a contributing factor
DPIA findingWhere a DPIA identifies retention period determination as an outstanding action
Vendor/processor changeOnboarding a new processor or service provider that will store personal data on behalf of the organization

Retention Impact Assessment Methodology

Phase 1: Scope and Context
RETENTION IMPACT ASSESSMENT — Orion Data Vault Corp
-----------------------------------------------------
Assessment Reference: RIA-2026-0019
Date: 2026-03-14
Assessor: [Name, Title]
DPO Review: [Name]

SECTION 1: PROCESSING ACTIVITY
- Name of processing activity: [Description]
- Business owner: [Name, Department]
- Purpose(s) of processing: [List all purposes]
- Legal basis for processing: [Art. 6(1)(a)-(f)]
- Data subjects: [Categories — e.g., customers, employees, job applicants]
- Data categories: [List all personal data elements]
- Special category data: [Yes/No — if yes, specify Art. 9 condition]
- Estimated data volume: [Records per year / total expected volume]
- Data sources: [Collected directly from data subject / obtained from third party]
- Data recipients: [Internal departments, processors, third parties]
- International transfers: [Yes/No — if yes, specify destination countries]
Phase 2: Regulatory Requirements Scan

Systematically identify all legal and regulatory requirements that mandate minimum retention:

Regulatory Scan Checklist
Regulatory DomainApplicable?Statute/RegulationMinimum PeriodNotes
Tax and fiscal□HMRC requirements; TMA 19706 yearsApplies to financial transaction data
Company law□Companies Act 20066 yearsApplies to accounting records
Employment law□Employment Rights Act 1996; Working Time Regulations 1998Varies (2-6 years)Applies to employee data
Health and safety□COSHH 2002; Ionising Radiations Regs 2017Up to 40 yearsApplies to health monitoring records
Financial services□MiFID II; FCA Handbook5-7 yearsApplies to investment client records
AML/CTF□MLR 2017; AMLD55 yearsApplies to CDD and transaction monitoring
Sector-specific□[Identify applicable sector regulations]VariesVaries
Contractual□Contract terms with clients/partnersPer contractReview contract clauses
Limitation periods□Limitation Act 19803-12 yearsContract (6y), tort (3y), deed (12y)
Data protection□GDPR; UK DPA 2018Storage limitation — no longer than necessaryDefault principle
Show full SKILL.md (305 more words)Show less
Jurisdictional Scan (for International Processing)
JurisdictionApplicable LawRetention RequirementConflict with Primary?
UK[Applicable UK statutes][Period]N/A (primary jurisdiction)
EU Member State(s)[Applicable EU/MS law][Period][Yes/No — resolve by applying longest]
US (if applicable)[SOX, CCPA, state law][Period][Yes/No — resolve]
Other[Specify][Period][Yes/No — resolve]
Phase 3: Purpose-Based Retention Determination

For each processing purpose, determine the retention period independently:

PURPOSE-BASED RETENTION ANALYSIS
---------------------------------

Purpose 1: [Primary processing purpose]
- Legal basis: [Art. 6(1)(x)]
- Data categories needed: [List]
- Duration of purpose: [How long does this purpose persist?]
- Retention period for this purpose: [Duration]
- Justification: [Why this period is necessary and proportionate]

Purpose 2: [Secondary processing purpose — if any]
- Legal basis: [Art. 6(1)(x)]
- Data categories needed: [List — should be subset of or equal to Purpose 1]
- Duration of purpose: [How long does this purpose persist?]
- Retention period for this purpose: [Duration]
- Justification: [Why this period is necessary and proportionate]

Statutory Override (if applicable):
- Statute: [Citation]
- Mandatory minimum: [Period]
- This overrides Purpose [X] period: [Yes/No]

RESULTING RETENTION PERIOD: [The longest justified period across all purposes
and statutory requirements, but no longer than the maximum necessary period]
Phase 4: Proportionality Review

The proportionality assessment ensures the retention period is no longer than necessary:

PROPORTIONALITY ASSESSMENT
----------------------------

1. NECESSITY
   - Is the proposed retention period the minimum necessary to achieve
     the stated purpose(s)? [Yes/No — justify]
   - Could the purpose be achieved with a shorter retention period?
     [Yes/No — justify]
   - Could the purpose be achieved with anonymized or aggregated data
     after a shorter period of identifiable retention? [Yes/No — justify]

2. DATA MINIMIZATION OVER TIME
   - Can some data elements be deleted or anonymized before the full
     retention period expires? [Yes/No — if yes, specify staged deletion]
   - Example: Full data retained for 12 months for service delivery;
     anonymized to aggregate statistics at 12 months; aggregates retained
     for 3 years for trend analysis.

3. ACCESS RESTRICTION OVER TIME
   - Should access be progressively restricted as the data ages?
   - Example: Active access for first 12 months; restricted to compliance
     team only for months 13-72; automated deletion at month 72.

4. RISK TO DATA SUBJECTS
   - What is the risk to data subjects from the proposed retention?
     [Low/Medium/High — justify]
   - Does longer retention increase breach impact? [Yes/No]
   - Are there specific data subject groups requiring heightened protection?
     (e.g., children, vulnerable individuals)

5. ALTERNATIVES TO RETENTION
   - Has anonymization been considered as an alternative? [Yes/No — outcome]
   - Has pseudonymization been considered to reduce risk during retention?
     [Yes/No — outcome]
   - Has data aggregation been considered? [Yes/No — outcome]

PROPORTIONALITY CONCLUSION:
The proposed retention period of [X] is / is not proportionate because:
[Detailed justification — 2-3 paragraphs]
Phase 5: Retention Period Recommendation
RETENTION PERIOD RECOMMENDATION
---------------------------------

Data Category: [Description]
Processing Activity: [Name]

RECOMMENDED RETENTION STRUCTURE:
┌──────────────────────┬─────────────────────┬──────────────────────────────┐
│ Phase                │ Duration            │ Data State                   │
├──────────────────────┼─────────────────────┼──────────────────────────────┤
│ Active processing    │ [Duration]          │ Full data, full access       │
│ Passive retention    │ [Duration]          │ Full data, restricted access │
│ Reduced retention    │ [Duration]          │ Minimized data, restricted   │
│ Anonymized retention │ [Duration/indefinite]│ Anonymized, no restrictions  │
│ Deletion             │ At end of above     │ Permanent deletion           │
└──────────────────────┴─────────────────────┴──────────────────────────────┘

Total identifiable retention period: [Sum of active + passive + reduced]
Retention trigger: [Event that starts the retention clock]
Deletion method: [Automated / Manual / Anonymization]

JUSTIFICATION SUMMARY:
[Concise summary of legal basis, statutory requirements, purpose analysis,
 and proportionality conclusion supporting this recommendation]

APPROVED BY:
- Business Owner: [Name] — Date: [YYYY-MM-DD]
- DPO: [Name] — Date: [YYYY-MM-DD]
- Legal (if statutory retention involved): [Name] — Date: [YYYY-MM-DD]

Implementation Checklist

After the RIA is approved, the following implementation steps must be completed:

StepActionResponsibleDeadline
1Add data category to retention schedule with approved periodDPOWithin 14 days of approval
2Configure automated deletion rules in relevant systemsITBefore processing commences
3Update Records of Processing Activities (ROPA) with retention periodDPOWithin 14 days of approval
4Update privacy notice to include retention period informationDPO / MarketingBefore processing commences
5Configure access restrictions per phased retention structureIT / SecurityBefore processing commences
6Update service provider/processor agreements if applicableLegal / ProcurementBefore processing commences
7Schedule first retention period reviewDPOSet for 12 months after processing starts
8Brief data owners and relevant staff on retention requirementsDPO / TrainingBefore processing commences

Review and Update

RIA Review Triggers
TriggerAction
Annual review dateReassess all RIA assumptions — purpose still valid, regulatory landscape unchanged
Legislative changeReassess statutory retention requirements
Processing changeFull RIA update if purpose, scope, or data categories change materially
Breach involving this dataAssess whether retention period contributed to breach scope; consider reduction
Data subject complaintReview retention period proportionality in light of complaint
Technology changeAssess whether new technology enables shorter retention or better anonymization
RIA Register

Orion Data Vault Corp maintains a register of all completed Retention Impact Assessments:

RIA REGISTER — Orion Data Vault Corp (Extract)

┌──────────────┬──────────────────────────┬────────────┬───────────────┬──────────────┬─────────────┐
│ RIA Ref      │ Processing Activity      │ Date       │ Retention     │ Status       │ Next Review │
│              │                          │ Completed  │ Period        │              │             │
├──────────────┼──────────────────────────┼────────────┼───────────────┼──────────────┼─────────────┤
│ RIA-2025-012 │ Customer loyalty program  │ 2025-06-15 │ Membership +  │ Active       │ 2026-06-15  │
│              │                          │            │ 2 years       │              │             │
├──────────────┼──────────────────────────┼────────────┼───────────────┼──────────────┼─────────────┤
│ RIA-2025-018 │ Employee wellbeing survey │ 2025-09-01 │ 12 months     │ Active       │ 2026-09-01  │
│              │                          │            │ (anonymize    │              │             │
│              │                          │            │ at 3 months)  │              │             │
├──────────────┼──────────────────────────┼────────────┼───────────────┼──────────────┼─────────────┤
│ RIA-2026-019 │ Vendor loyalty programme   │ 2026-03-14 │ 24 months     │ In progress  │ 2028-03-14  │
│              │ analytics                │            │ (review at    │              │             │
│              │                          │            │ 12 months)    │              │             │
└──────────────┴──────────────────────────┴────────────┴───────────────┴──────────────┴─────────────┘

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/retention-impact-assess of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Retention Impact Assess next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Retention Impact Assess compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Retention Impact Assess this skillmukul975/Privacy-Data-Protection-Skills301—~3.7kAutomated safety check: PassApache-2.0
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~2.3kAutomated safety check: PassMIT
Regulatory Audit Generatorzebbern/claude-code-guide4.7k1 repos~3.5kAutomated safety check: PassMIT
Reg Gap Analysisanthropics/claude-for-legal9.6k2 repos~2.6kAutomated safety check: PassApache-2.0
Policy OpaAgentSecOps/SecOpsAgentKit2201 repos~3.5kAutomated safety check: PassCustom licence
Compliance Checkjosstei/maestro-orchestrate465—~237Automated safety check: PassApache-2.0

Similar skills

  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Regulatory Audit Generator

    zebbern/claude-code-guide

    Builds compliance checklists for business scenarios involving GDPR, PIPL, or advertising/data laws.

    4.7k GitHub starsUsed in 1 repo~3.5k tokens
    Legal & ComplianceAuto-check passed
  • Reg Gap Analysis

    anthropics/claude-for-legal

    Official

    Diff a new or changed regulation against current privacy policy and practice — outputs a gap list and a remediation plan with owners and dates.

    9.6k GitHub starsUsed in 2 repos~2.6k tokens
    Legal & ComplianceAuto-check passed
  • Policy Opa

    AgentSecOps/SecOpsAgentKit

    Policy-as-code enforcement and compliance validation using Open Policy Agent (OPA).

    220 GitHub starsUsed in 1 repo~3.5k tokens
    Legal & ComplianceAuto-check passed
  • Compliance Check

    josstei/maestro-orchestrate

    Run a Maestro-style regulatory compliance review for GDPR/CCPA, cookie consent, data handling, and licensing

    465 GitHub stars~237 tokensUpdated 4 days ago
    Legal & ComplianceAuto-check passed
  • Implementing Compliance

    ancoleman/ai-design-components

    Implement and maintain compliance with SOC 2, HIPAA, PCI-DSS, and GDPR using unified control mapping, policy-as-code enforcement, and automated evidence collection.

    525 GitHub stars~4k tokensUpdated 10 mo ago
    Legal & ComplianceAuto-check passed

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    301 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    301 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    301 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    301 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about Retention Impact Assess

What does Retention Impact Assess do?

Conducts retention impact assessments for new processing activities to determine appropriate data retention periods. Retention Impact Assess is an agent skill from mukul975/Privacy-Data-Protection-Skills. Conducts retention impact assessments for new processing activities to determine appropriate data retention periods.

When should I use Retention Impact Assess?

Retention Impact Assess fits situations like: tasks that involve Privacy and GDPR; tasks that involve Regulatory compliance.

How do I install Retention Impact Assess in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill retention-impact-assess -a claude-code`. Or copy the skill folder (skills/privacy/retention-impact-assess in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/retention-impact-assess in your project. Claude Code loads it when a task matches its description.

How do I install Retention Impact Assess in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill retention-impact-assess -a codex`. Or copy the skill folder (skills/privacy/retention-impact-assess in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/retention-impact-assess in your project. Codex loads it when a task matches its description.

Can I use Retention Impact Assess in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill retention-impact-assess -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/retention-impact-assess, .gemini/skills/retention-impact-assess, .github/skills/retention-impact-assess and .opencode/skills/retention-impact-assess in your project.

What does Retention Impact Assess need to run?

Going by SKILL.md and its folder, Retention Impact Assess needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Retention Impact Assess access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Retention Impact Assess safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Retention Impact Assess use?

Retention Impact Assess is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Retention Impact Assess use?

About 3.7k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.5k tokens, read only when the agent opens those files.

What are the alternatives to Retention Impact Assess?

Skills that share tags, products or a category with Retention Impact Assess: Hipaa Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars), Regulatory Audit Generator (zebbern/claude-code-guide, 4.7k stars), Reg Gap Analysis (anthropics/claude-for-legal, 9.6k stars) and Policy Opa (AgentSecOps/SecOpsAgentKit, 220 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Retention Impact Assess?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.